Skip to content

Trust log: TPM2_Quote remote attestation #16

Description

@lamco-office

Add TPM2_Quote-based remote attestation: collect a TPM quote signed by an AIK, package it with the boot evidence, and make it available to a remote verifier (IETF RATS pattern).

Scope

  • TPM2_Quote call over the measured-boot PCRs LamBoot already extends (4 / 5 / 12).
  • Package the quote + boot-trust.log into an evidence bundle.
  • Bootloader-side code is bounded (~the quote call + report packaging). The heavy lift is the surrounding ecosystem (AIK provisioning, verifier/attestation server, certificate enrollment) which lives off-device.

Timing

v1.1+, pursued on concrete customer demand (compliance-driven deployments: FIPS / PCI-DSS / FedRAMP). Filed now so the capability is tracked rather than rediscovered.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions